Learn as you go
Choose an answer, reveal the key, and review available explanations, citations and candidate context.
25 questions free
Start guided practiceThe authorisation and risk management credential, formerly CAP: building a risk management programme, selecting and implementing controls, assessment, authorisation and continuous monitoring.
ISC2 does not publish numeric exam codes — CGRC is the common abbreviation.
ISC2 Governance, Risk and Compliance Certification is ISC2's professional-level governance, risk & compliance certification, referred to across the industry by the shorthand CGRC. The exam runs for 4 hours and presents up to 125 questions, with a pass mark of 700 / 1000 (scaled). It costs US$599 at the standard rate.
ISC2 publishes the syllabus as 7 weighted domains. Information Security Risk Management Program carries the most weight at 16%, and the three largest domains together account for roughly 48% of the scored content — worth knowing before you decide where study time goes.
Confirm these details on the official ISC2 page before booking — vendors adjust format and pricing without notice.
Some forms include unscored trial questions
Standard rate, before local taxes
The published exam guide for CGRC, in the vendor's own order.
01Information Security Risk Management Program
16%02Scope of the Information System
11%03Selection and Approval of Security and Privacy Controls
15%04Implementation of Security and Privacy Controls
16%05Assessment/Audit of Security and Privacy Controls
16%06Authorization/Approval of Information System
10%07Continuous Monitoring
16%Two years of cumulative work experience in one or more domains.
Professional level — Advanced credentials covering design, scale and trade-off decisions.
Preview 25 supported questions before unlocking the 27-question CGRC bank.
Community-contributedCompiled from publicly posted community exam discussions. Contributed by third parties rather than written here, so accuracy varies and most items carry no explanation. Progress and bookmarks stay in this browser.
Answer support: 0 explanations, 10 questions with candidate context and 0 questions with direct citations. Bank updated .
Choose an answer, reveal the key, and review available explanations, citations and candidate context.
25 questions free
Start guided practiceKeep answers hidden on the clock and review every miss only after you finish the public sample.
Free sample mock
Open timed mockWant the complete 27-question bank?
One Exam Pass unlocks this selected bank for 12 months with no renewal.
Compiled from exam discussions posted publicly by other people on ExamTopics. Copyright in each contribution rests with its original author; it is reproduced here for study. Not verified by us — most items carry no explanation. To request removal, see our content policy.
ISC2 lists up to 125 questions, to be completed in 4 hours. Question counts can vary slightly between exam forms, and unscored trial questions are sometimes included.
700 / 1000 (scaled). Confirm the current figure on the official exam page before booking, as vendors adjust cut scores when an exam form is refreshed.
The standard price is US$599. Local pricing, taxes and any retake policy vary by region, so check the official page for the figure that applies to you.
Two years of cumulative work experience in one or more domains.
The exam guide covers Information Security Risk Management Program, Scope of the Information System, Selection and Approval of Security and Privacy Controls, Implementation of Security and Privacy Controls and Assessment/Audit of Security and Privacy Controls, plus 2 further domains. The full weighted breakdown is listed above.
Yes — this exam has 27 practice questions available here, each with the correct answer marked. They are community-contributed, compiled from exam discussions posted publicly by other people rather than written here, and most do not carry an explanation.